Memory tagging catches bad memory accesses at the hardware level. Pixel 11 is the first flagship in three years to drop it, and no software update can bring it back.
Memory tagging is a hardware feature that catches bad memory accesses before they become exploits. Apple's iPhone 17 now ships it always-on. Google's new Pixel 11 does the opposite: it is the first Pixel in three years to drop memory tagging entirely, a cut no software update can reverse. The assessment is from a late-August post by GrapheneOS, the privacy-focused community fork of Android.
The missing feature is called Memory Tagging Extension, or MTE. It is a small piece of silicon that tags each block of memory with a short secret and checks the tag on every read or write. A bug, a buffer overflow, or a malicious input that points at the wrong memory address fails the check and is stopped, which is why MTE blocks a large share of the memory-corruption bugs that drive remote code execution. The check happens in hardware, on every memory access, with overhead small enough that the user never feels it. MTE has been available in Arm chips for years. The Pixel 8 (October 2023) was the first Pixel with it, and Android's Advanced Protection Mode can turn it on for a handful of processes on supported devices. GrapheneOS goes further: it enables MTE across the entire base operating system, the kernel included, with a per-app opt-in toggle for user-installed apps.
Pixel 11 changes that. According to GrapheneOS, the new Tensor G6 silicon does not include MTE, the firmware does not expose it, and the software cannot turn it on, because MTE is a hardware block that has to be present on the chip. The project says it completed only a partial port of GrapheneOS to the Pixel 11 after roughly a week of work and will not finish it, because the OS it would ship would not be the OS its users run. The Pixel 8 was the first generation with MTE. The Pixel 11 is the first to leave it out.
Apple's contrast is direct. On the iPhone 17, Apple's Memory Integrity Enforcement (MIE) uses the same Memory Tagging Extension as a core building block, in a high-quality always-on configuration, and ships it in the kernel and a large part of userland. Apple makes the same architectural claim with MIE: memory safety is a silicon-level concern, not a per-app toggle. The two flagship phone platforms are pulling in opposite directions on which side of the hardware boundary memory safety lives.
GrapheneOS is also explicit about how it reads Google's decision. In its post, the project says "it appears Google cut an important security feature to save money" and that the Pixel 11 is "a lot more expensive for an incremental improvement to the CPU, the same underpowered GPU and reduced RAM for the Pro base models." That is GrapheneOS's interpretation, and it should be read that way: no Google, Tensor, or Pixel team response to the MTE-cancellation claim has been published, so the motive framing belongs to the project that did the porting work, not to Google. The architectural consequence is documentable without that motive: the Pixel 11 ships without a hardware block the iPhone 17 ships with always on.
The cut does not make the Pixel 11 an unsecured phone. GrapheneOS's own post and TechTimes's summary both flag separate, real improvements: post-quantum verified boot using the ML-DSA signature scheme, replacement of Samsung's Shannon cellular-modem stack with the AOSP IMS implementation, and a Titan M3 security chip with stronger data-extraction protection in the Before-First-Unlock state. Those are real wins for the platform, and they cut against reading Pixel 11 as a security regression across the board. They are also exactly the kind of point defenses that MTE is not, because MTE is structural: it reduces the surface area of memory-corruption bugs, while ML-DSA and Titan M3 protect boot integrity and lockscreen data.
For the small community that runs GrapheneOS, the practical effect is sharper. The project says it has roughly 400,000 users, all in a self-selected privacy and security audience, and those users will be choosing between staying on older Pixels with full MTE coverage, moving to a non-Pixel device, or running a Pixel 11 with stock OS and accepting the gap. The Hacker News thread on the GrapheneOS post surfaces a separate, larger dispute over Google restricting GrapheneOS distribution on non-Samsung Android OEMs, which is a real fight but a different one: the MTE cut is about silicon, the distribution fight is about app stores and quotas.
The iPhone 17 and the Pixel 11 have made different calls about where memory safety lives: inside the silicon, or outside it. Apple shipped MTE in silicon on the iPhone 17. Google did not ship it in the Pixel 11's Tensor G6. No software patch closes that gap, which is why GrapheneOS can call it a regression a year from launch and still be right.